Malicious PDF — malware analysis report

Static analysis result for SHA-256 2af0ca0a2841e074…

MALICIOUS

PDF

40.9 KB Authoring application: OpenOffice.org First seen: 2021-02-09
MD5: c66a3c81b1c217a59dcbdc20ca923795 SHA-1: fa2d3596e224d1650e570679b4ba2938c246f373 SHA-256: 2af0ca0a2841e074b3b166679e68562fe0122585720027ee6bf530d437a3e8bd
152 Risk Score

Machine Learning

  • Nyx PDF Classifier malicious score 0.9999

Heuristics 3

  • ClamAV: Pdf.Phishing.TtraffRobotInstall-7605656-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Pdf.Phishing.TtraffRobotInstall-7605656-0
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://gardensoft.space/uploads/1/3/0/4/130483303/wugotowujuxane-puxoz.pdf In PDF document text
    • http://cashflowgrace.com/uploads/1/3/0/4/130477028/rokowov-zogotajapomafis-notito.pdfIn PDF document text
    • http://casarefugiopa.org/uploads/1/3/0/6/130621313/kuvofotoxurusufaj.pdfIn PDF document text
    • http://jackmillerslanding.net/uploads/1/3/0/3/130323900/3790276.pdfIn PDF document text
    • http://kellycarmichaelbooz.com/uploads/1/3/0/6/130621481/e798b18d.pdfIn PDF document text
    • http://bewife.kuhni-msc08.icu/uploads/2020/01/28/dumazoxaluzogizexi.pdfIn PDF document text
    • http://milestoneshomeinspections.net/uploads/1/3/0/5/130538816/130538816.html#free+fire+apkIn PDF document text

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off0000121a.bin pdf-font-stream PDF embedded font (sfnt) at offset 0x121A 10516 bytes
SHA-256: b52a69d534589cc0435544765a7cffd9d430b3dba845e1c73c798236e98cea91